PatchSiren

Plastic Labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Plastic Labs CVE published 2026-10-11

CVE-2026-108711

CVE-2026-108711 is a medium-severity vulnerability in Plastic Labs Honcho through version 3.3.0, allowing peer- or session-scoped API key holders to read workspace data via the POST /v3/workspaces endpoint. This issue arises from the get_or_create_workspace function only checking the workspace claim, enabling attackers to submit their parent workspace name and retrieve workspace metadata and configuration.